Skip to main content

Crew data is personal data, and it crosses borders

Crew data is personal data, and it crosses borders

A crew record is not a personnel file with a maritime flavour. It holds identity documents, visas, medical fitness certificates, next-of-kin details, bank details for wages, and a history of assessments. It is some of the most sensitive data an operator holds about anyone, and it does not sit still: it moves between the vessel, the manning office, the shore HR team, and occasionally an inspector standing on the ship.

That combination — highly sensitive, constantly in motion, crossing jurisdictions as the vessel does — is what makes crew data a harder problem than most HR data.

Why the maritime version is different

Three things separate it from a shore-based workforce. The crew is multinational, so the data subjects are covered by different national regimes and the operator cannot pick one and apply it everywhere. The workplace moves, so the same record is accessed from a vessel in one jurisdiction and an office in another on the same day. And a genuine operational need exists for third parties to see parts of it — port authorities, agents, training providers — which means the answer can never be simply to lock everything down.

Add the practical reality that a vessel is frequently offline, and the naive control model breaks: you cannot make every access decision contingent on reaching a shore server, because then nobody can check a medical certificate in open water.

"Least privilege is easy to state and hard to run, because the moment it obstructs a legitimate task at 0300 in open water, someone works around it."

The controls that survive contact with a ship

Access that follows the role rather than being granted case by case is the one that holds up offline, because the boundary travels with the user instead of being fetched. A master needs a different view of a crew record than a training coordinator, and neither needs the wage details the payroll team does. When those boundaries are attached to roles, a shipboard user keeps working through a connectivity gap inside limits that were already decided — rather than being blocked, or granted everything because blocking was worse.

Separation between operators matters for the same reason it matters commercially. Each cruise line runs on its own isolated data over one shared core, which is the mechanism that lets competing operators use the same platform. It is also the coarsest and therefore most reliable boundary: the question of whether one operator can see another's crew is not a permissions question at all.

The third control is the trail. Who read what and who changed it, retained in a form that survives a crew change and a rotation of shore staff. That record does double duty — it is what an inspector wants when they ask how a certificate came to be recorded, and it is the only way to answer the harder internal question of who has been looking at data they had no business in. The public detail on both is on access control that works across ship and shore.

What operators should ask a vendor

Two questions cut through most of it. First: what can a shipboard user still do when the link is down, and how was that boundary decided? An answer that amounts to "everything" or "nothing" both indicate the model has not been thought about. Second: show me the trail for a single crew record over the last ninety days. Either that exists as a product capability or it is a database query someone would have to write, and the difference tells you how the system was designed.

We will not tell you we hold a particular certification in a blog post; that is a question for a written answer against your own security questionnaire, and the page on requirements says as much. What we will say is that role-based access, per-operator isolation and a traceable history are how the platform is built, and they are the parts you can verify rather than take on trust.

If you are working through a data protection review for a crew platform, send us the questionnaire — that is a faster route to an accurate answer than any amount of marketing copy.

Chief DevSecOps

Alejandro keeps CruiseControl secure and reliable at fleet scale, from infrastructure to data protection.

Keep reading

When a procedure changes, who needs retraining?
Product

When a procedure changes, who needs retraining?

A signature is only as good as what you can prove about it
Product

A signature is only as good as what you can prove about it

Offline-first, sync-always: the platform at sea
Product

Offline-first, sync-always: the platform at sea

Contact Sales

Talk to our maritime team

Tell us about your operation and we’ll get back to you shortly.

0/1,000